What you govern, and the risk on it.
Business units, apps, vendors, processes, and AI agents live in one inventory. Put an app under the business unit that owns it, or at the company with no business unit. Each one carries its own compliance and residual risk, and those roll up.
| Item | Where it sits | Compliance | Residual risk |
|---|---|---|---|
| Acme | Company | 81% passing | $640K |
| Engineering | Business unit | Partial | $450K |
| Customer portal | App, under Engineering | Partial | $410K |
| Data warehouse | App, under Engineering | Passed | $40K |
| Employee laptops | Company level, 10,000 as one | One assessment | $120K |
| Stripe | Vendor, Tier 1, owned by Finance | In progress | $70K |
| Corporate identity | App, company level | Passed | $0 |
TruOps keeps an inventory of what you govern. An app can sit under the business unit that owns it, and that business unit’s compliance and residual risk are the sum of the apps under it. A vendor can be tied to several apps and processes at once, with its own owner and its own result. Company-wide apps, such as identity, sit at the company with no business unit, and roll straight up. Assess any item, or a group of the same assets. The result is saved on that item: compliance status, open findings, and residual risk in dollars, from likelihood, impact, and the controls in place. A person approves the score.
- Where an item sits
- Under a business unit, under a vendor, or at the company
- Also tied to
- The apps, processes, and vendors it depends on
- Written back
- Compliance, findings, and residual risk in dollars
- Rolls up
- From an app to the company
What you're probably using today
| What you use now | Where it falls short | With TruOps |
|---|---|---|
| Spreadsheets, shared drives, and email | Your program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork, and nothing is dated, so you can't show what was true last quarter. | Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so you have evidence for the whole period. |
| Enterprise GRC suites | They can model almost anything, but that flexibility usually runs through implementation partners and admins, so every change turns into a project. | AI reads your existing documents and sets up the program. Your first assessment opens pre-filled with sources, and you make changes by asking in plain language. |
| Point tools that don't connect | A TPRM portal here, a risk register there, findings in your ticketing tool, and the board pack in slides. Each tells its own story, so leadership gets three different answers. | One place for assessments, evidence, and risk. Upload a document, answer a question, or check a control once, and it counts everywhere it applies. |
Where each item sits
Ownership and dependence are different ties. A business unit owns the apps and processes that belong to it. A vendor can serve several of those at once, and still have its own owner. Anything that belongs to the whole company sits at company level, with no business unit.
| Item | Where it sits | Also tied to |
|---|---|---|
| Customer portal | Engineering | The payments vendor, and the refunds process |
| Data warehouse | Engineering | Finance, for the close |
| Corporate identity | The company | Every business unit that signs in |
| Employee laptops | The company, as one group | The people who use them |
| Payments vendor | Vendor, owned by Finance | The portal and the refunds process |
The assessment stays on the item
When an assessment finishes, its result is written onto the item it covered. Compliance status, open findings, and the date sit there. A risk assessment adds likelihood, impact, and a dollar figure for what remains after controls. Every dollar opens to the evidence behind it. A person approves the score before it is final.
The company number is the sum
A failed control on a server is visible on that server, on the app it belongs to, on the business unit, and on the company. Fifty servers failing the same check become one finding that lists all fifty. Residual risk in dollars rolls up the same path, so the company figure is the sum of the items under it.
The same assets, assessed once
Ten thousand laptops are one thing to assess. A group can follow a rule, such as every server in production, so new ones join on their own. The group carries one result, and its findings and dollars still roll up.
Kept current
Connect the tools that already list what you run. TruOps builds the inventory from them and keeps it current. You can also bring in a spreadsheet, add an item by hand, or add a type of your own, such as a data center, a contract, or an office.
How TruOps helps
- Where it sits
- Under a business unit, under a vendor, or at the company with no parent.
- More than one tie
- An app can relate to a vendor and a process as well as the unit that owns it.
- Results on the item
- Compliance, open findings, and residual risk in dollars, from the assessment.
- Roll-up
- From an app to the business unit, and the company.
- Groups
- Look-alike assets assessed once, including by a rule that new ones join.
- Your own types
- Data centers, contracts, offices, or anything else you govern.
Questions
What can go in the inventory?
Apps, vendors, business units, processes, and AI agents, plus any type you add, such as projects, data centers, contracts, or offices. An item can sit under a business unit, under a vendor, or at the company.
Does every item have to sit under a business unit?
No. Company-level items have no business unit. Others sit under the business unit or vendor that owns them.
Can one item relate to more than one other?
Yes. Ownership is one tie. A vendor can also be tied to the apps and processes that depend on it, and an app can be tied to more than one of those.
Where do the dollar figures come from?
From the risk assessment on that item: likelihood, impact, and the controls in place. The dollars roll up to the business unit and the company. A person approves the score, and every figure opens to the evidence behind it.
Do we have to assess thousands of servers one by one?
No. Group look-alikes and assess the group once. A group can follow a rule, such as Environment is Production, so new servers join on their own.
Can it find AI tools nobody approved?
Connect Okta or Entra and TruOps lists the AI tools your people sign in to, including ones nobody approved, next to the agents built on your own platforms.
Do we have to rip out the tools we already use?
No. TruOps connects to your cloud, identity, endpoint, vulnerability, and code tools. Spreadsheets, prior reports, and policies upload into the Data Room. If you're moving from a SOC 2 automation tool or an enterprise GRC suite, you bring over your frameworks, evidence, vendors, and risks.
Can we bring our existing assessments, control lists, and vendor files?
Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and risks, each linked to the file it came from, for you to review.
Related
Compliance, risk, vendor, and customer assessments in one place.
→PlatformVendor risk (TPRM)Tier vendors, read their evidence first, and ask only what it can't answer.
→PlatformControl testingEvery control tested continuously, with verified tests for your tools and AI-written tests for the rest.
→PlatformRisk managementRisks from anywhere, drafted by TruPilot, approved by a person, and tracked in ratings or dollars.
→PlatformMulti-tenantGive every client or entity its own space, with one view across all of them.
→RolesCISOAnswer the board with confidence and show the program's real progress.
→See it run on your own data.
Book 30 minutes with a GRC specialist. Bring a real document, like a SOC 2 report, risk register, or vendor list (redacted is fine), and we'll show TruOps AI working on it.